Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,734
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,701 - 6,720 of 13,553 CVEs
CVE-2026-22560 MEDIUM - 5.3

An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint.

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: Apr 10, 2026
Source: NVD
CVE-2026-40227 MEDIUM - 6.2

In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.

Vendor: systemd
Product: systemd
Published: Apr 10, 2026
Source: NVD
CVE-2026-40226 MEDIUM - 6.4

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

Vendor: systemd
Product: systemd
Published: Apr 10, 2026
Source: NVD
CVE-2026-40225 MEDIUM - 6.4

In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.

Vendor: systemd
Product: systemd
Published: Apr 10, 2026
Source: NVD
CVE-2026-40224 MEDIUM - 6.7

In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

Vendor: systemd
Product: systemd
Published: Apr 10, 2026
Source: NVD
CVE-2026-40223 MEDIUM - 4.7

In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.

Vendor: systemd
Product: systemd
Published: Apr 10, 2026
Source: NVD
CVE-2026-35594 MEDIUM - 6.5

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (GetLinkShareFromClaims in pkg/models/link_sharing.go) constructs authorization objects entirely from JWT claims without any server-side database validation. When a project owner ...

Vendor: go-vikunja
Product: vikunja
Published: Apr 10, 2026
Source: NVD

Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 825...

Vendor: Apache Software Foundation
Product: Apache Log4j JSON Template Layout
Published: Apr 10, 2026
Source: NVD

Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log messa...

Vendor: Apache Software Foundation
Product: Apache Log4j Core
Published: Apr 10, 2026
Source: NVD
CVE-2026-29043 MEDIUM - 5.5

HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can lead to a denial-of-service condition, and potentially further issues such as remot...

Vendor: HDFGroup
Product: hdf5
Published: Apr 10, 2026
Source: NVD
CVE-2026-31262 MEDIUM - 6.1

Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the URL parameter

Vendor: altenar
Product: sportsbook
Published: Apr 10, 2026
Source: NVD
CVE-2026-6068 MEDIUM - 6.5

NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or unexpected behavior...

Vendor: nasm
Product: netwide_assembler
Published: Apr 10, 2026
Source: NVD

Improper synchronization of the userTokens map in the API server in Canonical Jujuย 4.0.5,ย 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.

Vendor: go
Product: github.com/juju/juju
Published: Apr 10, 2026
Source: NVD
CVE-2021-47960 MEDIUM - 6.5

A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, ...

Vendor: Synology
Product: Synology SSL VPN Client
Published: Apr 10, 2026
Source: NVD
CVE-2026-6035 MEDIUM - 4.3

A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected element is an unknown function of the file /BranchManagement/ServiceAndSalesReport.php. The manipulation of the argument BRANCH_ID leads to cross site scripting. Remote exploitation of the attack is ...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6034 MEDIUM - 4.3

A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /BranchManagement/ProfitAndLossReport.php. Executing a manipulation of the argument BRANCH_ID can lead to cross site scripting. The attack may be launched remotely. The exploit ...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6033 MEDIUM - 6.3

A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedetailsfromstudent.php?eno=146891650. Executing a manipulation of the argument fname can lead to sql injection. The attack may be performed from remote. The exploit has been publicly ...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6032 MEDIUM - 4.3

A vulnerability was found in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkcheckout.php. Performing a manipulation of the argument serviceId results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made pub...

Published: Apr 10, 2026
Source: NVD
CVE-2026-5525 MEDIUM - 6.0

A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path of exactly 259 characters without a trailing backslash, the application appends a backslash and null terminator without proper bounds checkin...

Published: Apr 10, 2026
Source: NVD
CVE-2026-40212 MEDIUM - 5.4

OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs.

Vendor: OpenStack
Product: Skyline
Published: Apr 10, 2026
Source: NVD